(TLP:CLEAR) Backdoor Identified in Chinese-Made Zbtlink Router Firmware – ENDLESSDOORS
Created: Thursday, August 6, 2026 - 15:19
Categories: Cybersecurity, Security Preparedness
Summary: VulnCheck’s zero-day research team has disclosed ENDLESSDOORS, a command and control (C2) backdoor that is built into the firmware of routers made by Zbtlink, a brand of the Chinese manufacturer Shenzhen Zhibotong Electronics. The devices are sold worldwide under both the Zbtlink and Wiflyer names, and the researchers estimate at least 100,000 affected units are deployed globally. This is not the result of a compromise. According to VulnCheck, the implant is installed at the factory and started at boot by the vendor’s own init (initialization) script, so affected routers reach out to attacker-controllable infrastructure immediately upon connection.
VulnCheck indicates that the devices continuously phone home to a small set of hardcoded endpoints, contacting them roughly every 35 seconds. The channel has no authentication or encryption. Once a router checks in, anyone who controls the destination domain or IP, or who sits along the network path, can send commands that execute as root or open a fully interactive root shell. Because the device dials outbound, the attack does not require the router to be reachable from the internet, so a unit behind several layers of firewall is just as exposed as one with a public IP. VulnCheck has assigned the issue CVE-2026-66747 and confirmed the implant in 21 firmware images covering more than 20 models, including the CPE2801, the WE and WG series, and the Z8102AX-2DSIM. There is no fixed firmware, and VulnCheck did not pursue coordinated disclosure because the behavior appears to be intended vendor functionality rather than a patchable defect.
Analyst Note: Low-cost cellular and small office routers frequently appear at the edges of water and wastewater environments, in remote pump stations, lift stations, tank sites, temporary or contractor-installed connections, and other locations where a cheap 5G or LTE gateway is the fastest way to get a signal. A backdoor of this kind is well suited to the pre-positioning and quiet persistence that groups such as Volt Typhoon have pursued against U.S. critical infrastructure. A router carrying ENDLESSDOORS is not a vulnerable device waiting to be exploited; it is a device already reaching out and waiting for orders, and whoever answers gains root-level access and a foothold to reach other systems on the same network.
The practical takeaway for utilities is to find and remove these devices rather than try to fix them. Members can start by inventorying network equipment by model number rather than brand label, since the same hardware is rebranded and resold under many names, and by looking for Zbtlink, ZBT, ZBTWiFi, Wiflyer, and unbranded cellular CPE of unclear origin. Where devices are identified, WaterISAC suggests members follow VulnCheck’s recommendations listed in its “What to do about it” section:
- Match purchasing records, remote site kit, and contractor-installed equipment against the affected model list and treat unbranded cellular gateways as suspect until confirmed otherwise.
- On any device you can access, check for two userland “kworker” processes and for the files /usr/sbin/kworker, /usr/lib/librctl.so, /etc/kworker.cfg, and /etc/init.d/skworker.
- Block and alert on the known endpoints at both the egress firewall and the DNS resolver, and watch for outbound connections on ports 7000 and 7001, particularly from network infrastructure segments.
- Replace confirmed devices where possible, or at minimum move them behind strict egress control and treat their local network as untrusted.
The confirmed ENDLESSDOORS indicators are the domains zbtctl[.]epplink[.]net, online-string[.]com, and rbdg4nzqadui[.]wikaba[.]com, and the IP addresses 47.100.190[.]96, 47.107.224[.]89, 45.32.81[.]152, and 43.248.136[.]125. VulnCheck has also published Suricata, Snort, and YARA detection content in its report.
Original Source: https://www.vulncheck.com/blog/zbt-endlessdoors
Additional Reading:
- Chinese-made Zbtlink routers have backdoor, researchers say
- People’s Republic of China State-Sponsored Actors Compromising and Maintaining Persistent Access to U.S. Critical Infrastructure
- CISA’s Secure by Demand Guide: How Software Customers Can Drive a Secure Technology Ecosystem
Related WaterISAC PIRs: 6, 6.1, 7, 7.1, 8, 11, 12
